Skip to content

Add a dependency lifecycle policy #1471

Open
@psschwei

Description

@psschwei

#SecuritySlam

What would you like to be added:

A dependency lifecycle policy doc

Why is this needed:

It is a component of the OSSF Security Insights spec (and shows up in CLOMonitor), so adding this doc would boost the project's score.

Completion requirements:

This enhancement requires the following artifacts:

  • dependency lifecycle policy doc
  • updated SECURITY-INSIGHTS.yml file to include the relevant section

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.kind/featureCategorizes issue or PR as related to a new feature.sig/releaseCategorizes an issue or PR as relevant to SIG Release.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions